๐ŸŽ„

CertoMetrics - 15% OFF Special Discount Offer - Ends In:

0d 00h 00m 00s
Coupon code: SALE2026

Isaca Certified Information Systems Auditor (CISA)

Get full access to the updated question bank and confidently prepare for your exam.

Vendor

Isaca

Certification

Governance Risk and Security

Content

844 Qs

Status

Verified

Updated

2 days ago

Test the Practice Engine

Experience our interactive testing environment with free demo questions

Launch Free Demo
Best Value Bundle

Premium Bundle

Complete Success Suite

$143 $79

Save $64 Instantly

  • โœ“
    Full PDF + Interactive Engine Everything you need to pass
  • โœ“
    All Advanced Question Types Drag & Drop, Hotspots, Case Studies
  • โœ“
    Priority 24/7 Expert Support Direct line to certification leads
  • โœ“
    90 Days Free Priority Updates Stay current as exams change

Success Metric

98.4% Pass Rate

Verified by 15k+ Students
Secure Checkout
Popular

Standard Simulation

Practice Engine

$74

One-Time Payment

  • Web-Based (Zero Install)
  • Real Testing Environment Virtual & Practice Modes
  • Interactive Engine Drag & Drop, Hotspots
  • 60 Days Free Updates

Compatible with All Devices

Chrome
Verified Secure Checkout

Basic Tier

PDF Study Guide

$69

Digital Access

  • โœ“ Exam Questions (PDF)
  • โœ“ Mobile Friendly
  • โœ“ 60 Days Updates
Download Free Sample PDF

Verified 100-Question Preview (CISA)

Secure Checkout

Verified Community

The CertoMetrics Standard.

Recommend the #1 platform for verified Isaca certification resources.

Success Network

Help a Colleague Succeed.

Invite a peer to get their own updated CISA prep kit.

Exam Overview

The ISACA Certified Information Systems Auditor (CISA) certification is globally recognized as the gold standard for IT audit, control, and security professionals. Earning your CISA demonstrates a proven ability to assess vulnerabilities, report on compliance, and institute controls within an enterprise. It validates your expertise in managing IT risks and ensuring the integrity, confidentiality, and availability of information systems. This credential significantly enhances career opportunities, fosters professional credibility, and positions you as a trusted advisor in an increasingly complex digital landscape. CISA holders are essential in safeguarding organizational assets and ensuring robust IT governance, making it a pivotal achievement for anyone serious about a career in information systems auditing and assurance.

Questions

150

Passing Score

450/800 (scaled score)

Duration

240 Minutes

Difficulty

Expert

Level

Professional

Skills Measured

Information System Auditing Process
Governance and Management of IT
Information Systems Acquisition, Development, and Implementation
Information Systems Operations and Business Resilience
Protection of Information Assets

Career Path

Target Roles

IT Auditor Information Security Manager Compliance Officer

Common Questions

Is the material up to date?

Yes. We update our question bank weekly to match the latest Isaca standards. You get free updates for 90 days.

What format do I get?

You get instant access to both the **PDF** (for reading) and our **Premium Test Engine** (for exam simulation).

Is there a guarantee?

Absolutely. If you fail the CISA exam using our materials, we offer a full money-back guarantee.

When do I get the download?

Instantly. The download link is available in your dashboard immediately after payment is confirmed.

Free Study Guide Samples

Previewing updated CISA bank (100 Questions).

QUESTION 1

Which of the following is the GREATEST benefit of using file integrity monitoring (FIM) when securing critical systems?

A
FIM enables legacy hardware to be used beyond its expected life cycle.
B
FIM enables Dev Sec Ops to work closely with the security operations center (SOC).
C
FIM identifies suspicious system alterations such as changes to files or directories.
D
FIM allows the organization to stop performing traditional change management practices.

Correct Option: C

QUESTION 2

An organization has determined that a trusted insider has been able to bypass controls and embezzle organizational funds. Which type of audit would be MOST helpful when providing evidence to law enforcement?

A
Regulatory audit
B
Integrated audit
C
Financial audit
D
Forensic audit

Correct Option: D

QUESTION 3

Which of the following is the BEST protection against forged email?

A
Digital signature
B
Encryption
C
Application level firewall
D
Identification of sending host

Correct Option: A

QUESTION 4

An IS auditor is reviewing an organization's disaster recovery plan (DRP) to determine whether operations can continue in the event of a disruption. Which of the following would provide the auditor with the BEST evidence confirming that the organization's plan is effective?

A
Regular updates to the DRP
B
Emergency response training
C
Updated contact lists in the DRP
D
Tabletop scenario exercises

Correct Option: D

QUESTION 5

An organization saves confidential information in a file with password protection, and the file is placed in a shared folder. An attacker has stolen this information by obtaining the password through social engineering. Implementing which of the following would BEST enable the organization to prevent this type of incident in the future?

A
Access history log review by the business manager
B
Multi-factor authentication (MFA)
C
Security awareness programs for employees
D
File encryption along with password protection

Correct Option: B

QUESTION 6

An IS auditor is examining cryptographic key management with a focus on ensuring the protection of cryptographic keys against modification and unauthorized disclosure. Which of the following should be reviewed FIRST?

A
Key storage
B
Key rotation
C
Key generation
D
Key policies

Correct Option: A

QUESTION 7

Which of the following is the BEST indication of an effective problem management process?

A
Incidents are assigned to engineers immediately.
B
The number of repeat incidents is reduced.
C
The time to close an incident is reduced.
D
Incidents are logged in a centralized system.

Correct Option: B

QUESTION 8

Which of the following findings should be of GREATEST concern during an audit of IT governance and management?

A
The IT strategy development process is not documented.
B
The organization is not aligned with an international IT control standard.
C
There is no IT representation in business strategy committee meetings,
D
There is no chief information security officer (CISO) position.

Correct Option: C

QUESTION 9

A small business unit is implementing a control self-assessment (CSA) program and leveraging the internal audit function to test its internal controls annually. Which of the following is the MOST significant benefit of this approach?

A
Line management is more motivated to avoid control exceptions.
B
Business owners can focus more on their core roles.
C
Risks are detected earlier.
D
Compliance costs are reduced.

Correct Option: C

QUESTION 10

Which of the following data controls is MOST helpful in verifying that the data received by an application is the same as the data sent by a remote application?

A
Functional acknowledgments
B
Hash checking
C
Validity checking
D
File header records

Correct Option: B

QUESTION 11

Which of the following would BEST help ensure data integrity during transmission?

A
Hashing with SHA-256
B
Symmetric encryption with AES-256
C
Asymmetric encryption with RSA
D
Hashing with MD5

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 12

Which of the following is MOST important when evaluating the design effectiveness of murti-factor authentication (MFA)?

A
Reviewing the physical controls related to the storage of the hardware tokens
B
Evaluating whether false rejection and false acceptance rates have been adequately defined
C
Ensuring separation is maintained by storing the two factors in separate databases
D
Determining the identification process for each factor and ensuring they are synchronized

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 13

A business application has crashed, and the database has been restored from backup. To ensure data integrity, which of the following will provide the BEST assurance?

A
Root cause identification by technical specialists and the business
B
Roll-forward confirmation from the database team
C
Recovery review and sign-off from the relevant business department
D
Results from entry of test data by an independent party

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 14

Which of the following should be of GREATEST concern for an IS auditor when reviewing user account policies?

A
There is no policy requiring employees to sign nondisclosure agreements (NDAs).โ€™
B
There is no policy in place for ongoing security awareness training.
C
There is no policy to revoke previous access rights when employees change roles.
D
There is no policy to revoke an employee's system access upon termination.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 15

In which of the following system development life cycle (SDLC) phases would an IS auditor expect to find that controls have been incorporated into system specifications?

A
Development
B
Feasibility
C
Design
D
Implementation

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 16

Which of the following is an IS auditor's BEST approach when low-risk anomalies have been identified?

A
Ask auditees to promptly remediate the anomalies.
B
Document the anomalies in audit work papers.
C
Update the audit plan to include the information collected during the audit.
D
Deprioritize further testing of the anomalies and refocus on issues with higher risk.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 17

Which of the following would be of GREATEST concern to an IS auditor reviewing continuous integration / continuous deployment (CI/CD) practices?

A
If all pipeline tests pass, changes are allowed to be deployed into production without manual review.
B
The time between deployments has varied from four hours to two weeks.
C
Dynamic application security testing (DAST) is not performed for every build.
D
Critical security test failures within the pipeline do not stop production deployment.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 18

An organization's senior management thinks current security controls may be excessive and requests an IS auditor's advice on how to assess the adequacy Of current measures, What is the auditor's BEST recommendation to management?

A
Introduce automated security monitoring tools.
B
Re-evaluate the organization's risk and control framework,
C
Perform correlation analysis between incidents and investments.
D
Downgrade security controls on low-risk systems.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 19

A steering committee established to oversee an organization's digital transformation program is MOST likely to be involved with which of the following activities?

A
Preparing project status reports
B
Documenting requirements
C
Designing interface controls
D
Reviewing escalated project issues

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 20

After validating the recovery time objective (RTO) for a time-critical system. which of the following should an IS auditor do NEXT to ensure the metric is aligned with the organization's disaster recovery goals?

A
Verify the RTO is effectively integrated into disaster recovery plans (DRPs).
B
Formulate an incident response strategy that incorporates the metric.
C
Perform a business impact analysis (BIA) if one has not been recently conducted.
D
Reassess and enhance data backup strategies that support the defined RTO.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 21

Which of the following should be a concern to an IS auditor reviewing an organization's use of a major cloud provider for Infrastructure as a Service (IaaS)?

A
The cloud governance policy was not reviewed within the last year by the IT department.
B
The IaaS service is connected to the organizations network via a virtual private network (VPN).
C
End users are able to create their own cloud server instances.
D
The IaaS service relies on the organization's active directory domain.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 22

Which of the following controls is the BEST recommendation to prevent the skimming of debit or credit card data in point of sale (POS) systems?

A
Encryption
B
Biometric authentication
C
Hashing
D
Chip and PIN

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 23

Which of the following should be the GREATEST concern to an IS auditor evaluating an organization's policies?

A
Policies are not updated on an annual basis.
B
Policies are not formally acknowledged and signed by employees-
C
Policies do not identify adequate controls or processes to protect the organization.
D
Policies are not reviewed by the chief information officer (CIO).

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 24

An IS auditor is performing an audit of a large organization's operating system maintenance procedures. Which of the following findings presents the GREATEST risk?

A
The configuration management database (CMDB) is not up to date.
B
Critical patches are applied immediately while others follow quarterly release cycles.
C
Some internal servers cannot be patched due to software incompatibility.
D
Vulnerability testing is not performed on the development servers.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 25

Which of the following is the PRIMARY objective of enterprise architecture (EA)?

A
Enforcing the IT policy across the organization
B
Managing and planning for IT investments
C
Executing customized development and delivery of projects
D
Maintaining detailed system documentation

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 26

An organization has replaced its can center with Al chatbots that autonomously learn new responses through internet queries and customer conversation history. Which of the following would an IS auditor tasked with verifying IT controls consider to be the GREATEST risk?

A
The model's operations may be difficult for the IT team to document
B
It may be difficult to audit the model due to the lack of a suitable framework
C
The model may not result in expected efficiencies.
D
The model may not generate accurate responses due to overfitting

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 27

Which of the following BEST enables an organization's information security team to correlate and aggregate log files from different sources?

A
Endpoint security monitoring system
B
Intrusion detection system (IDS)
C
Security information and event management (SIEM)
D
Vulnerability and threat manage

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 28

During a network security audit: which of the following would an IS auditor consider to be the GREATEST risk?

A
The network device inventory is incomplete.
B
The network firewall policy has not been approved.
C
Network penetration tests are performed on an ad hoc basis.
D
Network firewall rules have not been recently updated.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 29

Which of the following would MOST likely be detailed in an audit charter?

A
Appointments needed with key process owners
B
Right to access relevant information
C
Timeline of the audit engagement
D
List of evidence required for the audit

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 30

The PRIMARY objective of performing a post-implementation review is to verify that the system is:

A
supported by user documentation.
B
achieving the required objectives.
C
aligned with the business strategy,
D
stabilized in the production environment.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 31

An IS auditor is reviewing an organizations recently adopted generative Al system. which requires large amounts of data that may include personal information Which of the following BEST mitigates data privacy risk related to generative Al?

A
End-user security awareness training
B
A data loss prevention (DLP) solution
C
Data anonymization and acceptable use standards
D
Continuous monitoring to detect anomalies and model drift

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 32

Which of the following is the MOST important consideration when evaluating the data retention policy for a global organization with regional offices in multiple countries?

A
The policy aligns with local laws and regulations.
B
The policy aligns with global best practices.
C
The policy aligns with business goals and objectives.
D
The policy aligns with corporate policies and practices.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 33

In planning a major system development project, function point analysis would assist in:

A
estimating the elapsed time of the project.
B
analyzing the functions undertaken by system users as an aid to job redesign.
C
determining the business functions undertaken by a system or program.
D
estimating the size of a system development task.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 34

An IS auditor has traced the source of a transaction fraud to the desktop system of an e-business staff member who is on leave. Which of the following is the BEST way for the auditor to

ensure the success of the investigation?

A
Immediately seal off the attacked system and block all access until after the investigation.
B
Interview the business staff and ask them to provide details of recent system activities.
C
Reboot the attacked system and promptly review log files and file timestamps.
D
Create an image of the attacked system and dump the memory on a file for review.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 35

In response to a finding that several vendor-supplied security fixes had not been applied to a business-critical application. management has agreed to apply all the security patches- During follow-up procedures, which of the following is MOST important for the IS auditor to verify?

A
Parallel testing has been performed,
B
Progression testing has been performed.
C
Code compression testing has been performed.
D
Regression testing has been performed.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 36

When utilizing attribute sampling, which of the following would cause the sample size to increase?

A
Acceptable risk level increase
B
Tolerable error rate decrease
C
Expected error rate decrease
D
Population size decrease

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 37

Which of the following is the GREATEST benefit of an operational log management system?

A
Reducing data storage requirements
B
Reducing lag in application logging system calls
C
Enabling real-time insights into system operations
D
Optimizing computing resource allocation

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 38

An organization's email service is hosted by a third pat-M and the service level agreement (SLA) requires 99.9% availability. An IS auditor finds that the service has not met its availability level for the past five months, Which of the following is the auditor's BEST recommendation?

A
Withhold payment until availability service level is met.
B
Self-host an email server and monitor availability.
C
Discontinue use of the email service provider.
D
Review the service provider relationship and consider alternatives.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 39

Which of the following is the PRIMARY objective when encrypting a database?

A
Protecting data from unauthorized changes
B
Preserving the ability to access data securely
C
Protecting data from unauthorized viewing
D
Preserving the ability to query data

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 40

After reviewing an organization's patching policy and process documentation. an IS auditor identifies unpatched Internet of Things (IoT) devices. Which of the following should the auditor do FIRST to determine the root cause?

A
Verify the devices are listed in the asset inventory.
B
Review manufacturer IoT device documentation.
C
Determine the location of the deployed devices.
D
Review the organization's most recent risk assessment on IoT devices.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 41

The PRIMARY benefit of using a statistical sampling method in an IS audit is to:

A
avoid residual risk.
B
mitigate audit risk.
C
determine the tolerable error rate.
D
objectively quantify the probability of error

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 42

An IS auditor finds a user account where privileged access is not appropriate for the user's role. Which of the following would provide the BEST evidence to determine whether the risk of this access has been exploited?

A
Documented approval for the account
B
Activity log for the account
C
Last logon date for the account
D
Interview with the user's manager

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 43

Which of the following is PRIMARILY used in data loss prevention (DLP) solutions to prevent the unauthorized transfer of sensitive data over email?

A
Virtual private network (VPN)
B
Transport Layer security (TLS)
C
Network address translation
D
Deep packet inspection

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 44

Which of the following should an IS auditor verify FIRST when reviewing operational resilience?

A
Critical business processes have been identified.
B
Plausible disruption scenarios have been developed.
C
Business continuity plans (BCPs) have been prepared.
D
A business resource map has been created.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 45

During a business impact analysis (BIA) exercise. it was identified that a business process is highly dependent on a particular IT system. Which of the following is the MOST important consideration in this situation?

A
System access
B
System redundancy
C
System integrity
D
System capacity

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 46

Robotic process automation (RPA) tools have been implemented to automate manual processes across an organization. Which of the following is the BEST recommendation to address concerns regarding which processes should be automated?

A
Perform a life cycle cost-benefit analysis.
B
Assess cost savings for each RPA tool used across the organization.
C
Require reporting of cost per automated process.
D
Centralize RPA development to one team.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 47

An organization is disposing of a system containing sensitive data and has deleted all files from the hard disk. An IS auditor should be concerned because:

A
deleting the files logically does not overwrite the files' physical data.
B
deleting all files separately is not as efficient as formatting the hard disk.
C
deleted data cannot easily be retrieved.
D
backup copies of files were not deleted as well

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 48

An organization is implementing a new enterprise resource planning (ERP) system. From a system performance management perspective.

Which Of the following would pose the GREATEST concern for an IS auditor?

A
Escalation procedures for resolution of capacity and performance issues have not been developed.
B
The impact of the new system on existing enterprise infrastructure has not been evaluated.
C
Service level agreements (SLAs) for the new system have not been defined.
D
Performance metrics and dashboards have not been created.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 49

Which of the following would be of GREATEST concern to an IS auditor providing support to a financial audit team?

A
Application controls can only be tested in production due to the lack of a test environment
B
Completeness and accuracy of critical reports cannot be verified to source systems
C
Manual review controls are performed due to the lack of systemic separation of duties
D
Password parameters differ from corporate policy for the financial application

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 50

In which of the following situations would an IS auditor MOST likely utilize data analytics?

A
When logging tools are available
B
When performing controls-based testing
C
When there is a large population
D
When data is obtained from unreliable sources

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 51

In the context of audit algorithms. which of the following is a characteristic of a supervised learning model?

A
The audit algorithm does not require any data to make predictions.
B
The audit algorithm needs to be constantly monitored by an auditor.
C
The audit algorithm teams from labeled data where the outcome is known.
D
The audit algorithm teams by itself without any monitoring by an auditor

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 52

Which of the following can only be provided by asymmetric encryption?

A
256-bit key length
B
Nonrepudiation
C
Data availability
D
Information privacy

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 53

During the forensic investigation of a cyberattack involving credit card data: which of the following is MOST important to ensure?

A
All staff in the payment card unit are interviewed.
B
The company's payment platforms are blocked.
C
Adequate card security features are activated.
D
Proper chain of custody is maintained.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 54

A core system fails a week after a scheduled update, causing an outage that impacts service. Which of the following is MOST important for incident management to focus on when addressing

the issue?

A
Analyzing the root cause of the outage to ensure the incident will not reoccur
B
Restoring the system to operational state as quickly as possible
C
Rolling back the unsuccessful change to the previous state
D
Ensuring all resolution steps are fully documented prior to retuming the system to service

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 55

An organization uses an Al-driven file scanning solution to detect malware in incoming email attachments. Which of the following is MOST important for an IS auditor to assess?

A
The ability of the Al model to rapidly adapt to new and evolving threats
B
The number of false positives generated by the file scanner
C
The test results Of the Al model prior to deployment
D
The speed at which files are scanned before being delivered to users

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 56

An IS auditor is reviewing vulnerability scanning results of an organizations critical systems. Which of the following is the BEST way to validate that the vulnerabilities have been remediated

A
Review patch management documentation.
B
Review change management documentation for remediation.
C
Re-scan the vulnerable systems.
D
Interview owners of vulnerability scanning systems for evidence.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 57

Which of the following non-audit activities may impair an IS auditor's independence and objectivity?

A
Reviewing secure software development guidelines adopted by an organization
B
Evaluating a third-pan,' customer satisfaction survey
C
Providing advice on an IT project management framework
D
Designing security controls for a new cloud-based workforce management system

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 58

Based on best practice, which types of accounts should be disabled for interactive login?

A
Service accounts
B
Console accounts
C
Local accounts
D
Administrator accounts

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 59

Which of the following is MOST important to consider when developing a service level agreement (SLA)?

A
Provisions for regulatory requirements that impact the end userS businesses
B
Description of the services from the viewpoint of the provider
C
Description of the services from the viewpoint of the client organization
D
Detailed identification of work to be completed

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 60

During a follow-up audit, an IS auditor learns that management has deferred the implementation of a previously agreed-upon recommendation. What js the responsibility of the auditor?

A
Obtain commitment from management to implement the recommendations.
B
Amend the final report to reflect the decision to defer the implementation.
C
Report the decision to defer the implementation to the steering committee.
D
Assess the impact of any risks the decision may pose to the organization.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 61

The PRIMARY objective of the disaster recovery planning process is to:

A
align incident response time with industry best practices.
B
comply with regulatory requirements.
C
ensure data can be recovered completely
D
minimize the operational interruption.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 62

An IS auditor evaluating the resilience of a network with a high-availability requirement should be MOST concerned if:

A
the network architecture is geographically dispersed.
B
the network servers are clustered in one site.
C
only one hot site is ready for activation.
D
diverse routing is implemented for the network.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 63

Which of the following controls BEST ensures the integrity of data exchanged between two systems?

A
Hash values
B
Encryption
C
Control totals
D
Data classification

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 64

During the review of a system disruption incident, an IS auditor notes that IT support staff were put in a position to make decisions beyond their level of authority. Which of the following is the

BEST recommendation to help prevent this situation in the future?

A
Implement fallback options.
B
Introduce escalation protocols.
C
Enable an emergency access ID.
D
Develop a competency matrix.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 65

An IS auditor finds that the access-controlled doors to a work area are kept unlocked during power outages. Which of the following is the auditor's BEST course of action?

A
Report the finding to management as high-risk,
B
Determine whether there are compensating controls.
C
Confirm whether the practice complies with the security policy.
D
Recommend keeping the doors locked at all times.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 66

Which of the following is MOST important for an IS auditor to ensure is in place for protecting APIs?

A
User training and awareness
B
Least privilege
C
24/7 monitoring of API activity
D
Malware protection

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 67

Which of the following sampling methods is MOST appropriate when assessing a population to focus on specific risk areas?

A
Stop-or-go
B
Attribute
C
Judgmental
D
Statistical

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 68

To reduce operational costs, IT management plans to reduce the number of servers currently used to run business applications. Which of the following is MOST helpful to review when identifying which servers are no longer required?

A
Server CPU usage trends
B
Contract with the server vendor
C
Performance feedback from the user community
D
Mean time between failure (MTBF) of each server

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 69

Which of the following is the BEST way for an organization to reduce its risk associated with the collection and protection of personal information?

A
Limit the amount of personal information collected to industry standards.
B
Limit the amount of personal information collected to the minimum required.
C
Only allow remote access to personal information from an alternate site.
D
Perform a privacy impact assessment (PIA).

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 70

Which of the following poses the GREATEST risk to an organization that is rapidly scaling its use of robotic process automation (RPA)?

A
Reliance on cloud-based solutions
B
Increased infrastructure costs
C
Vendor lock-in
D
Lack of governance

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 71

Which cloud deployment model is MOST likely to be customizable?

A
Private
B
Public
C
Hybrid
D
Community

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 72

An IS auditor is providing input to an RFP to acquire a financial application system- Which of the following is MOST important for the auditor to recommend?

A
Audit trails should be included in the design-
B
Vendor employee background checks should be conducted regularly.
C
Potential suppliers should have experience in the relevant area.
D
The application should meet the organization's requirements.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 73

The quality assurance (QA) team is testing a new e-ticketing application prior to go live to ensure that sales tax is calculated and applied correctly.

Which of the following should be Of GREATEST concern?

A
User procedures to manage the e-ticketing application are still being drafted.
B
user acceptance criteria for the test performed are not clearly defined.
C
The tax schedules are not uploaded into the production database.
D
The project manager wants to delay implementation by a few days.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 74

Visitors to a data center are required to present an ID and pre-approved documents. Which type of control has been implemented?

A
Administrative control
B
Preventive control
C
Corrective control
D
Detective control

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 75

Which of the following would be of GREATEST concern to an IS auditor reviewing an organization's disaster recovery plans (DRPs)?

A
Tabletop exercises are performed irregularly.
B
Management has not signed off on plans-
C
Plans are not current, but testing is performed annually,
D
Plans are updated annually but not tested.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 76

Which of the following is MOST important when assembling an internal team to perform penetration testing for the organization?

A
Gain agreement from management on timing and scope
B
Obtain a listing of key systems for testing from management
C
Perform a scan and identify in-scope assets.
D
Query the company directory to find privileged users.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 77

An IS auditor is reviewing an organization's cloud access security broker (CASB) solution- Which of the following is MOST important for the auditor to verify?

A
Cloud processes are resilient.
B
Users are periodically recertified.
C
Users are centrally managed.
D
Cloud services are classified.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 78

When reviewing an organization's enterprise architecture (EA): which of the following is an IS auditor MOST likely to find within the EA documentation?

A
Protocols used to communicate between systems
B
Roadmaps showing the evolution from current state to future state
C
Contact information for key resources within the IT department
D
Detailed encryption standards

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 79

An IS auditor is reviewing documentation for an IT department procedure for adding a firewall rule. Which of the following should be of GREATEST concem to the IS auditor?

A
The procedure does not include data flow diagrams for administrators.
B
The procedure was created by a junior member of the team.
C
The procedure has not been approved by senior management.
D
The procedure has not been reviewed in the past five years.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 80

Which of the following is MOST important to consider when developing a business continuity plan (BCP)?

A
Results of enterprise risk assessment
B
Executive buy-in of the plan
C
Results of annual tabletop exercises
D
Updated business impact analysis (BIA)

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 81

An IS auditor is reviewing the business continuity plan (BCP) for a business unit and notes an approved cloud service defined in the list of processes. Which of the following wouId be the auditorโ€™s GREATEST concern?

A
A free tier of the cloud service is being used.
B
The cloud service has not been tested as part of the BCP
C
The contract for the cloud service does not specify an IT representative.
D
The cloud vendor has not provided an updated contact list

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 82

Which of the following is MOST important for an IS auditor to review prior to the migration of acquired software into production?

A
Expected return on investment (ROI)
B
Vendor testing report
C
User acceptance test (UAT) report
D
Source code escrow agreement

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 83

A disaster recovery plan (DRP) should include steps for:

A
quantifying application control risk.
B
restoring operational data.
C
negotiating contracts with disaster planning consultants.
D
identifying application control requirements.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 84

An IS auditor validates data extracted from an enterprise resource planning (ERP) system to ensure the data meets financial industry standards. Which type of audit is being conducted?

A
Compliance audit
B
Operational audit
C
Administrative audit
D
Forensic audit

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 85

Which of the following groups would be MOST appropriate to participate in a security training that includes detailed information about the operation of technical security controls?

A
System users
B
System administrators
C
System analysts
D
System owners

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 86

Which of the following reliably associates users with their public keys and includes attributes that uniquely identify the users?

A
Encryption
B
Nonrepudiation
C
Mufti-factor authentication (MFA)
D
Digital certificate

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 87

Which of the following should be the PRIMARY focus for any network design that deploys a Zero Trust architecture?

A
Maintaining network router operating system versions
B
Protecting technology resources
C
Ensuring a vendor-agnostic environment
D
Protecting network segments

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 88

An IS auditor is evaluating the risk associated with moving from one database management system (DBMS) to another. Which of the following would be MOST helpful to ensure the integrity of the system throughout the change?

A
Preserving the same data reports
B
Preserving the same data interfaces
C
Preserving the same data classifications
D
Preserving the same data structure

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 89

Which of the following would be an IS auditor's GREATEST concern when reviewing an organization's implementation of a forensic readiness plan?

A
Acritical business application's performance declined after new policies for data collection were implemented.
B
System owners were not notified of the retention requirements for emails subject to litigation holds.
C
Organization-wide training has not been provided on the tools used to access collected information.
D
The cost of storing collected digital evidence has increased significantly over the past six months.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 90

The FIRST step in an incident response plan is to:

A
notify the head of the IT department.
B
initiate root cause analysis.
C
validate the incident.
D
isolate systems impacted by the incident.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 91

Which of the following is the MOST important consideration when designing IT controls?

A
Control assessments are automated and regularly reported
B
Control descriptions and policy documents are reviewed and updated.
C
Control design workshops are organized annually with IT leaders
D
Controls are mapped to risk and aligned with business objectives.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 92

Which of the following features would BEST address risk associated with data at rest when evaluating a data loss prevention (DLP) solution?

A
File movement detection
B
Storage-scanning technology
C
Enforcement of access policies
D
Printing of scan files

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 93

An organization is integrating two systems for real-time API communication. Which of the following is the BEST approach to ensure secure authentication between the two applications before going live?

A
Conduct penetration testing to identify vulnerabilities that might allow unauthenticated access.
B
Review firewall configuration and rules across both system environments.
C
Review security incident and event management (SIEM) solution logs.
D
Perform user acceptance testing (UAT) for user login interfaces and the user authentication mechanism.

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 94

In operational log management, which of the following BEST ensures the availability of log data?

A
Regular cleaning and sorting of log data
B
Regular testing of log data backups
C
Regular analysis and reporting of log data
D
Regular compression of stored log data

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 95

Which of the following controls is MOST effective for discovering unauthorized cloud service usage in an organization's corporate network?

A
Scanning network computers for currently installed software
B
Conducting reviews of firewall logs
C
Reviewing invoices for cloud services
D
Asking department heads what cloud services they are using

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 96

Which of the following is MOST important for an IS auditor to consider when reviewing a data retention policy?

A
Regulatory obligations
B
Data confidentiality
C
Business requirements
D
Industry best practices

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 97

An IS auditor observes that a large number of departed employees have not been removed from the accounts payable system. Which of the following is MOST important to determine in order to assess the risk?

A
The frequency of user access reviews performed by management
B
The process for terminating access of departed employees
C
The frequency of intrusion attempts associated with the accounts payable system
D
The ability of departed employees to actually access the system

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 98

An IS auditor is reviewing the system development practices of an organization that is about to move from a Waterfall to an Agile approach.

Which of the following is MOST important for the auditor to focus on as a result of this move?

A
Code documentation
B
Release management
C
Capacity planning
D
Secure code review

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 99

Which of the following activities should be separated in an organization's incident management processes?

A
Recording and classifying incidents
B
Collecting and analyzing logs from devices
C
Identifying root causes and recommending workarounds
D
Initiating and closing error logs

Premium Solution Locked

Unlock all 844 answers & explanations

QUESTION 100

Which of the following should an IS auditor be MOST concerned with when reviewing the IT asset disposal process?

A
Certificate of destruction
B
Data stored on the asset
C
Monetary value of the asset
D
Data migration to the new asset

Premium Solution Locked

Unlock all 844 answers & explanations

Full Question Bank Locked

You have reached the end of the free study guide preview. Upgrade now to unlock all 844 questions and the full simulation engine.

Customer Reviews

5 / 5
(15,000+ verified)
5
100%
4
0%
3
0%
2
0%
1
0%

Global Community Feedback

DM

David M.

Verified Student

"The practice engine is incredible. It feels exactly like the real testing environment and helped me build so much confidence."

SJ

Sarah J.

Premium Member

"The PDF is very well organized and the explanations for the answers are actually helpful, not just random text."

MC

Michael C.

Verified Buyer

"I was skeptical, but the content is high quality and definitely worth the price. I passed on my first try!"

Need Assistance?

> Our expert support team is available to assist you with any inquiries about our exam materials.

Contact Support
Average response: < 24 Hours

Get Exam Updates

> Subscribe to receive instant notifications on new questions and exclusive flash sales.

* Join 5,000+ students getting weekly updates

Support Chat โ— Active Now

๐Ÿ‘‹ Hi! How can we help you pass your exam?

Enter email to start chatting